gonsoz42 Posted December 9, 2007 Report Share Posted December 9, 2007 Dear Moderators!in these days, my uTorrent client starts to download some files (not all), but stops at 0.2 or 0.3 %, and displays in the status field: "Error: Access denied." here are my processes, what was running while the error bash in:full picture: http://anouk.fpn.hu/kepek/processes.jpgplease help me, because this is very annoying.. and my only idea was the nod32 and the Comodo firewall.. but i did shut down both, and the situation doesn't changed thx in advance! Link to comment Share on other sites More sharing options...
DreadWingKnight Posted December 9, 2007 Report Share Posted December 9, 2007 post a hijackthis log please. Link to comment Share on other sites More sharing options...
gonsoz42 Posted December 9, 2007 Author Report Share Posted December 9, 2007 here it is:Logfile of HijackThis v1.97.7Scan saved at 19:22:56, on 2007. 12. 09.Platform: Unknown Windows (WinNT 5.02.3790 SP2)MSIE: Internet Explorer v7.00 (7.00.6000.16544)Running processes:C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exeC:\WINDOWS\SysWOW64\ctfmon.exeC:\Program Files (x86)\ASUS\GamerOSD\GamerOSD.exeC:\Program Files (x86)\Java\jre1.6.0_03\bin\jusched.exeC:\WINDOWS\system32\CTHELPER.EXEC:\Program Files (x86)\eMule\emule.exeC:\Program Files (x86)\DAEMON Tools\daemon.exeC:\Program Files (x86)\Hide IP Platinum\hideippla.exeC:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\uTorrent\uTorrent.exeC:\Program Files (x86)\IncrediMail\bin\IncMail.exeC:\Program Files (x86)\IncrediMail\bin\ImApp.exeC:\Program Files (x86)\Macromedia\Dreamweaver MX\Dreamweaver.exeF:\VegyesNetFruit\prg-felhasznaloi\firewall_virus_spam\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 219.93.178.162:3128R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://go.microsoft.com/fwlink/?LinkId=74005F2 - REG:system.ini: UserInit=userinitO2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_03\bin\ssv.dllO4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME (x86)\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNCO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMENameO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXEO4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXEO4 - HKLM\..\Run: [CtxfiReg] CTXFIREG.exe /FAIL2O8 - Extra context menu item: E&xportálás a Microsoft Excel programba - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)O9 - Extra button: Research (HKLM)O9 - Extra button: Messenger (HKLM)O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)O11 - Options group: [iNTERNATIONAL] International*O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{30567F62-D12F-4D44-A6F4-2084824B2D8E}: NameServer = 84.2.44.1,84.2.46.1 Link to comment Share on other sites More sharing options...
jewelisheaven Posted December 9, 2007 Report Share Posted December 9, 2007 I have read some posts about ESET being a pain when you allow it access to the download directory. Link to comment Share on other sites More sharing options...
ajones81 Posted December 9, 2007 Report Share Posted December 9, 2007 Google Unlocker or Process Explorer and check which program has grabbed hold of those files. Link to comment Share on other sites More sharing options...
gonsoz42 Posted December 10, 2007 Author Report Share Posted December 10, 2007 thx guys, i'm on it... hope it'll resolved soon. :-/my first thought was ESET, but it didn't cause problem before.***edit:( i've ran Process Explorer... but i don't know what should i see in it.. there are no shady processes.. how can i find "which program has grabbed hold of those files" ?(please help! i feel myself so lamer)******edit2:here is the Process Explorer's savefile:a text file******edit3:i think, the problem is only with the torents whose contains .exe files... mhmm... i wonder, what program can block these files..? Link to comment Share on other sites More sharing options...
jewelisheaven Posted December 10, 2007 Report Share Posted December 10, 2007 Though you can deduce which process has open said files, it is not as simple as click-search.There are two modes for the lower pane in Process Explorer, DLL mode (Ctrl-D) and Handle mode (Ctrl-H).You will need to switch to handle mode, and I have found sorting by file flags helps alot.All files opened by uT for example have -RW-.What you will need to do, for the specific files you are searching is to start at a likely process and work up or down.. Note you can skip the whole process tree for services... Unless you have some sort of filesystem protection service startup. Link to comment Share on other sites More sharing options...
gonsoz42 Posted December 10, 2007 Author Report Share Posted December 10, 2007 thanks a lot!!!!!.. i go sleep now, but tomorrow i'll try these steps.. (first i have to understand and translate ) Link to comment Share on other sites More sharing options...
jewelisheaven Posted December 10, 2007 Report Share Posted December 10, 2007 If you want pictures I can provide them Link to comment Share on other sites More sharing options...
gonsoz42 Posted December 11, 2007 Author Report Share Posted December 11, 2007 ooh i've tried my best, but it's too difficult to me.so.. i have the handle mode, and sorting by 'file share flags' .. but i can't find any "-RW-" (i don't even know what is it..)"What you will need to do, for the specific files you are searching is to start at a likely process and work up or down.. Note you can skip the whole process tree for services... Unless you have some sort of filesystem protection service startup."work up or down.. hmm.. this is not clear to me :-j - where should i click?what are the "specific files" ?and the process tree... is this in the upper half in the ProcessExpl. window?and the "filesystem protection" - is it the NOD32 (eg.) ? - but in this case why this doesn't stop the torrent files (which contains .exe) from public trackers?here is a picture, that's where i'm now:i know i'm so difficult person, with a lack of skills in this case, but please help me further Link to comment Share on other sites More sharing options...
jewelisheaven Posted December 11, 2007 Report Share Posted December 11, 2007 You selected the right thing up-top. As far as the lower pane.. you switched to Ctrl-h But I too don't see any flags... Did you sort the other way (flip downward arrow to upward-facing)? :/Also, I recommended searching ALL processes (to be thorough). But if you don't see uT having the file open for writing... there's a problem there as well. What you will see, especially on "indexing services" or "filesystem protection" is that the process (up top) has LOTS of files open that you are using, for example downloading in uT. This can cause problems if they open it in W (write) mode, which means then uT cannot access it. Link to comment Share on other sites More sharing options...
gonsoz42 Posted December 11, 2007 Author Report Share Posted December 11, 2007 i don't see any flags like -RW- only "---" as you see on the picture... is there a problem? (yes, i know.. but i don't know how is it)i've examine the processes, but i don"t see -RW- anywhere.***okay, i've lost the line... what should i do with what?? "indexing services" or "filesystem protection" - i haven't seen these in the ProcExp.. did you mean the explorer.exe's sub-processes??i've seen only one uTorrent.exe line with purple color in the upper screen, and i don't find the "W" sign (for write mode).. uhh.. i'm so sad.. and feel so silly :-/ Link to comment Share on other sites More sharing options...
jewelisheaven Posted December 11, 2007 Report Share Posted December 11, 2007 I don't know why you wouldn't see any files opened, ESPECIALLY by uT.Here is a logging instance of uT I use for test downloads.you will notice aside from windows DLLs I have open my read directory "M:\New Folder", my write directory "J:\Download\Done", and the logfile "O:\µTorrent\beta\1\6838.1207.log"Edit: I notice in the pic there is a folder I presume you use "D:\downloads\torrents"... why it does not show write flags, i am at a loss... It is possible that is a quirk of Vista.What I meant about the interference programs that do "real-time monitoring" is that in the bottom pane there you would see ITs process, as well as uTs process trying to access the file, rendering uT's ability to write to it useless..But given you don't see any write flags.. Perhaps you can try double sorting? or sort by "name" descending (downward arrow). That should put utorrent.exe process information first, followed by open files (at least it does that on my opened filesystem) Link to comment Share on other sites More sharing options...
sludgeman Posted December 12, 2007 Report Share Posted December 12, 2007 hi im new to the forums...i have had utorrent for a fair while though and had no problems with it...until now :Slast couple of days i reformatted my pc and since then i have been getting the access denied problems too.i ran that hijackthis as you suggested to other people here are the reuslts:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 12:39:42 AM, on 13/12/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16574)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\RUNDLL32.EXEC:\Program Files\Analog Devices\Core\smax4pnp.exeC:\Program Files\Analog Devices\SoundMAX\Smax4.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exeC:\PROGRA~1\INTERN~2\mum.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Alwil Software\Avast4\ashMaiSv.exeC:\Program Files\Alwil Software\Avast4\ashWebSv.exeC:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exeC:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\MSN Messenger\msnmsgr.exeC:\Program Files\MSN Messenger\usnsvc.exeC:\Program Files\iTunes\iTunes.exeC:\Program Files\uTorrent\uTorrent.exeC:\PROGRA~1\MOZILL~1\FIREFOX.EXEC:\WINDOWS\system32\svchost.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.vso-software.fr/affiliate/thankyou.php?p=ConvertXtoDVDO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNCO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMENameO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exeO4 - HKLM\..\Run: [soundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /trayO4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeO4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"O4 - HKCU\..\Run: [internodeUsage] C:\PROGRA~1\INTERN~2\mum.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{F9C872EE-10C1-4A30-9516-412A350B5B01}: NameServer = 192.231.203.132,192.231.203.3O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exeO23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exeO23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe--End of file - 5424 bytesAny idea from that what my issue might be? Link to comment Share on other sites More sharing options...
jewelisheaven Posted December 12, 2007 Report Share Posted December 12, 2007 First I thank you for researching a bit before reporting a problem.However, as others recently experiencing this problem also have this, could you tell me what this is:O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exeWhat version / type of Ahead software are you running.Generally speaking, ANY indexer which has access to the uT download directory can cause problems. Sure not all do it, but a majority interfere due to applying file permissions settings which essentially "lock out" uT from continued access and therefore an inability to continue to download.Also, has any of this software been recently installed. I know you said it is a reformat, but did you try uT before installing all of your software? Link to comment Share on other sites More sharing options...
gonsoz42 Posted December 12, 2007 Author Report Share Posted December 12, 2007 dear Jewelisheaven! :-oo i don't understand why my uT has different properties (lack of -RW- and others).. i'll go and set up a temporary folder like you, nad a finished folder, and try to check this again then.and i have win xp pro x64 - this can be the root of the problem :-Shmm-hmm.. i'll be back at tomorrow with new results or maybe new questions good night! Link to comment Share on other sites More sharing options...
jewelisheaven Posted December 12, 2007 Report Share Posted December 12, 2007 While I don't use x64 XP I do know it got more testing than the newer Vista x64.As far as write flags, if the files are being written to but they're not being shown.. I'm assuming it's something to do with x86x64 -> x86 (32-bit) translation... but I have no idea.As a bruteforce method to the solution can you turn OFF / close process of ALL real-time monitors (anti virus / software firewall / internet protection ) and re-enable them one by one re-trying to start one torrent to see if you can identify which process is causing this. OH OH!! What version / suite of Nero software are you using. Both the indexer and backup service may indeed be trying to write to the files. So if you could try those processes first... I'd hope any additional features can be turned off in the main Nero configuration screen... So please try with Nero first to see if that's the problem.Recently (was there an update??) we've had alot of people with problems exhibit the same services in their HJT logs. Link to comment Share on other sites More sharing options...
Firon Posted December 12, 2007 Report Share Posted December 12, 2007 Nero's indexer is the cause, probably. Disable Nero Scout. Link to comment Share on other sites More sharing options...
sludgeman Posted December 13, 2007 Report Share Posted December 13, 2007 Thanks for the response Jewel and Firon. I have nero7 suite, its the same as i had before the format, infact i havent got any different programs than before.I have disbaled nero scout and i still got the problems. even after reinstalling utorrent and getting new ports etc.Im currently uninstalling nero 7 to see if this helps and will post back any resultsCheersedit: still getting the problem after uninstalling nero Link to comment Share on other sites More sharing options...
jewelisheaven Posted December 13, 2007 Report Share Posted December 13, 2007 What about AVAST? Anti virus really REALLY don't like files being written to as they're scanning.Is it possible prior to the reformat you had a rule to exclude your uT and uT download folders from real time scanning?Thanks for all the checking. I hope you don't think we look down on all of these services, it's just that ... from a usability standpoint, the more programs you have running, the more possible conflict there can be. And I'm not talking about all programs, but for example there was this guy who made a torrent and started seeding it, then he couldn't make any OTHER seeds since his media player added tags to his files... And that's only one instance that occurred recently. Link to comment Share on other sites More sharing options...
sludgeman Posted December 13, 2007 Report Share Posted December 13, 2007 hmm well i have disabled my firewall, turned off avast, disabled nero scout and still no success lol -.-" im not sure really what else to do...maybe a different torrent program? Link to comment Share on other sites More sharing options...
Firon Posted December 13, 2007 Report Share Posted December 13, 2007 Do you have iTunes set to index media files? It might be doing it too... :/I doubt it's Avast, though. Link to comment Share on other sites More sharing options...
sludgeman Posted December 13, 2007 Report Share Posted December 13, 2007 no unfortunatley i dont think its that... all my itunes settings are manual and i dont let itunes automate anything if i can help it Link to comment Share on other sites More sharing options...
gonsoz42 Posted December 13, 2007 Author Report Share Posted December 13, 2007 Jewelisheaven :DDD !!!!You are a miracle ))on the grounds of your "bruteforce" method;1. i've finally figured out, that the Comodo firewall was the guilty application2. i was checking the settings3. and TA-DAAAM!.. one little checkbox was the problem's sourceso, THANK YOU very much! )i'm so glad and happy it i've got problems with uT in the future, i'll be back trustfully bye-bye for now! Link to comment Share on other sites More sharing options...
sludgeman Posted December 15, 2007 Report Share Posted December 15, 2007 ok so despite being determined to get this problem of mine fixed...i decided to download BitTorrent instead of using uTorrent...it works fine without any system changes and all my applications running without any problems...sigh oh wells at least i can d/l again xDThanks again for your advice guys, i really appreciate it Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.